[HEXANE](https://attack.mitre.org/groups/G1001) has used a PowerShell-based keylogger named `kl.ps1`.(Citation: SecureWorks August 2019)(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has downloaded additional payloads and malicious scripts onto a compromised host.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has run `cmdkey` on victim machines to identify stored credentials.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used a [Mimikatz](https://attack.mitre.org/software/S0002)-based tool and a PowerShell script to steal passwords from Google Chrome.(Citation: Kaspersky Lyceum October 2021)
Useful?
Suggested · co-occurring (unverified)
These entities are frequently mentioned together in source material; co-occurrence is not a verified relationship.
CountryIsraelco-mentioned in 1 item
MalwareCavern frameworkco-mentioned in 1 item
SectorGovernmentco-mentioned in 1 item
MalwareCavern Agentco-mentioned in 1 item
TechniqueT1071co-mentioned in 1 item
TechniqueT1574.002co-mentioned in 1 item
SectorIT providersco-mentioned in 1 item
Malwaren-HTCommp.dllco-mentioned in 1 item
Typed relationships
Curated links to related activity — not this actor's alias list. Claimed personas are marked unverified; overlap / subgroup edges describe a related but distinct cluster, never the same actor.
Related cluster — overlap, not the same actor
Cavern Manticorehigh confidencesource ↗HEXANE (G1001) and Cavern Manticore share TTP/tooling overlap but Cavern Manticore is a distinct 2026 Check Point cluster; kept separate with a technical-overlap edge (NOT identity).
Related
Semantically related in the corpus — a discovery aid, not asserted attribution.
[HEXANE](https://attack.mitre.org/groups/G1001) has used [Ping](https://attack.mitre.org/software/S0097) and `tracert` for network discovery.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used tools including [BITSAdmin](https://attack.mitre.org/software/S0190) to test internet connectivity from compromised hosts.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has run `whoami` on compromised machines to identify the current user.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used [netstat](https://attack.mitre.org/software/S0104) to monitor connections to specific ports.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used a PowerShell-based keylogging tool to capture the window title.(Citation: SecureWorks August 2019)
[HEXANE](https://attack.mitre.org/groups/G1001) has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.(Citation: SecureWorks August 2019)(Citation: Dragos Hexane)(Citation: ClearSky Siamesekitten August 2021)(C
[HEXANE](https://attack.mitre.org/groups/G1001) has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.(Citation: SecureWorks August 2019)(Citation: Kaspersky APT Trends Q1 April 2021)(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used a scheduled task to establish persistence for a keylogger.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used a VisualBasic script named `MicrosoftUpdator.vbs` for execution of a PowerShell keylogger.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has used cloud services, including OneDrive, for data exfiltration.(Citation: Microsoft POLONIUM June 2022)
[HEXANE](https://attack.mitre.org/groups/G1001) has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.(Citation: SecureWorks August 2019)
[HEXANE](https://attack.mitre.org/groups/G1001) has identified specific potential victims at targeted organizations.(Citation: ClearSky Siamesekitten August 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has identified executives, HR, and IT staff at victim organizations for further targeting.(Citation: SecureWorks August 2019)(Citation: ClearSky Siamesekitten August 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has targeted executives, human resources staff, and IT personnel for spearphishing.(Citation: SecureWorks August 2019)(Citation: ClearSky Siamesekitten August 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has acquired, and sometimes customized, open source tools such as [Mimikatz](https://attack.mitre.org/software/S0002), [Empire](https://attack.mitre.org/software/S0363), VNC remote access software, and DIG.net.(Citation: Kaspersky Lyceum October 2021)(
[HEXANE](https://attack.mitre.org/groups/G1001) has staged malware on fraudulent websites set up to impersonate targeted organizations.(Citation: ClearSky Siamesekitten August 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.(Citation: SecureWorks August 2019)(Citation: Dragos Hexane)(Citation: ClearSky Siamesekitten August 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has established email accounts for use in domain registration including for ProtonMail addresses.(Citation: Kaspersky Lyceum October 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has established fraudulent LinkedIn accounts impersonating HR department employees to target potential victims with fake job offers.(Citation: ClearSky Siamesekitten August 2021)
[HEXANE](https://attack.mitre.org/groups/G1001) has set up custom DNS servers to send commands to compromised hosts via TXT records.(Citation: Zscaler Lyceum DnsSystem June 2022)
[HEXANE](https://attack.mitre.org/groups/G1001) has used Base64-encoded scripts.(Citation: Kaspersky Lyceum October 2021)
Associated software
12 linked · 12 ATT&CK-attributed, 0 curated
Malware and tools this actor is known to use. ATT&CK-attributed rows are MITRE's own software↔group relationships; curated rows fill the gap for MENA actors ATT&CK doesn't track — treat those as analyst assessment, not authoritative attribution.
ATT&CK-attributed · 12
Sourced from MITRE ATT&CK's own uses relationships for this group.
Regional co-occurrence is association, not prediction. These techniques appeared alongside HEXANE (Lyceum)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 10 techniques
Advanced Anti-Phishing T1534partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1110significantConditional AccessT1110.003significantID ProtectionT1110partialID ProtectionT1110.003partialIdentity Secure ScoreT1110partialIdentity Secure ScoreT1110.003partialMultifactor AuthenticationT1110significantMultifactor AuthenticationT1110.003significantPasswordless AuthenticationT1110significantPasswordless AuthenticationT1110.003significantPassword PolicyT1110partialPassword PolicyT1110.003partialPassword ProtectionT1110partialPassword ProtectionT1110.003partialRole Based Access ControlT1059minimalAntimalwareT1027significantAntimalwareT1059significantAntimalwareT1059.001significantAntimalwareT1204significantAntimalwareT1204.002significantAntiSpamT1534significantInformation ProtectionT1567significant
detect · 22 techniques
Adaptive Application Control IntegrationT1204partialAdaptive Application Control IntegrationT1204.002partialAdvanced Anti-Phishing T1534partialApp GovernanceT1110significantApp GovernanceT1110.003significantAnti-SpoofingT1534significantAdvanced Threat HuntingT1110significantAdvanced Threat HuntingT1110.003significantAdvanced Threat HuntingT1534significantAdvanced Threat HuntingT1546significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1016.001minimalDefender for Cloud AppsT1027.010partial
respond · 9 techniques
Automated Investigation and ResponseT1204.002significantAutomated Investigation and ResponseT1534significantAutomated Investigation and ResponseT1567significantIncident ResponseT1059minimalIncident ResponseT1110minimalIncident ResponseT1110.003minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1204significantQuarantine PoliciesT1204.002significantQuarantine PoliciesT1534significantSafe AttachmentsT1204significantSafe AttachmentsT1204.002significantATT&CK Simulation TrainingT1204partial
Countermeasures · D3FEND
Defensive techniques that counter HEXANE (Lyceum)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.